> Source: [sk165716](https://support.checkpoint.com/results/sk/sk165716)

# sk165716 - Policy installation fails on gateway with "Error code 0-2000240"

| Property | Value |
|----------|-------|
| Solution ID | sk165716 |
| Date Created | 2020-03-25 |
| Last Modified | 2021-11-15 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Policy installation fails on gateway with error code 0-2000240 when Drop templates option is enabled and there is a huge list of IP range.

* Policy installation debug shows:   

  `
  ...;[cpu_11];[fw4_0];ifn 31, range 20: X.X.X.X - 223.255.255.255;`  
  `
  ...;[cpu_11];[fw4_0];ifn 31, range 21: 240.0.0.0 - 255.255.255.254;`  
  `
  ...;[cpu_11];[fw4_0];cphwd_prepare_anti_spoofing_enforce: Interface 31 has 22 ranges list;`  
  `
  ...;[cpu_11];[fw4_0];cphwd_prepare_anti_spoofing_enforce: Interface 31 is external;`  
  `
  ...;[cpu_11];[fw4_0];cphwd_prepare_anti_spoofing_enforce: Interface 31 Anti spoofing violations will be tracked;`  
  `
  ...;[cpu_11];[fw4_0];cphwd_prepare_anti_spoofing_enforce: Interface 31 Anti spoofing will be enforced in monitor only mode;`  
  `
  ...;[cpu_11];[fw4_0];24346: X.X.X.X - Y.Y.Y.Y;`  
  `
  ...;[cpu_11];[fw4_0];24347: X.X.X.X - Y.Y.Y.Y;`  
  `
  ...;[cpu_11];[fw4_0];24348: X.X.X.X - Y.Y.Y.Y;`  

* Reboot on affected member may resolve the issue for some time.
* fwk.elg (USFW/VSX) or dmesg (kernel mode) shows "cphwd_multik_prepare_api_stat_cb: expired.;" after policy installation failed

## Cause

Huge IP range list is causing issue during Security policy compilation.

<br />

## Solution

This problem was fixed. The fix is included in:

* [Check Point R81](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk166715)
* [Jumbo Hotfix Accumulator for R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk165456) since Take 38
* [Jumbo Hotfix Accumulator for R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152) since Take 210
* [Jumbo Hotfix Accumulator for R80.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk137592) since Take 160

<br />

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
